Documentation

API Reference

Vesta’s API server exposes a RESTful API for every platform operation — the CLI and web UI are both built on it. All paths below are relative to /api/v1 unless noted.

Authentication

Most endpoints require a bearer token. Create one under API tokens, then:

curl -H "Authorization: Bearer <token>" https://<api-host>/api/v1/apps

Tokens carry scopes (read, write, deploy) and users carry roles (admin, developer, viewer). Write endpoints reject the viewer role.

Unauthenticated endpoints

MethodPathDescription
GET/healthzHealth check (outside /api/v1)
GET/setup/statusWhether first-run setup is complete
POST/setupCreate the first admin account
POST/auth/loginLogin and receive a JWT
GET/auth/oauth/:providerStart an OAuth login
GET/auth/forgot-password/statusWhether password reset is configured
POST/auth/forgot-passwordRequest a password reset
POST/auth/reset-passwordComplete a password reset
POST/auth/accept-inviteAccept a team invitation
POST/webhooks/:providerInbound webhook (verified by signature)
POST/webhooks/:provider/:connectionIdInbound webhook for a specific git connection

Projects & environments

MethodPathDescription
GET/projectsList projects
POST/projectsCreate a project
GET/projects/:projectIdGet a project
PUT/projects/:projectIdUpdate a project
DELETE/projects/:projectIdDelete a project
GET/projects/:projectId/environmentsList environments
POST/projects/:projectId/environmentsCreate an environment
PUT/projects/:projectId/environments/:envUpdate an environment
DELETE/projects/:projectId/environments/:envDelete an environment
POST/projects/:projectId/environments/:env/cloneClone an environment
GET/projects/:projectId/membersList project members
GET/projects/:projectId/dependenciesApp dependency graph

Apps

Apps live inside a project, so they are created under the project and addressed by app ID afterwards.

MethodPathDescription
GET/appsList all apps
POST/projects/:projectId/appsCreate an app
GET/projects/:projectId/appsList apps in a project
GET/apps/:appIdGet app details
PUT/apps/:appIdUpdate an app
DELETE/apps/:appIdDelete an app
POST/apps/:appId/cloneClone an app
GET/pod-sizesAvailable pod size presets

Deployments

MethodPathDescription
POST/apps/:appId/deployDeploy an app
POST/apps/:appId/rollbackRoll back to a previous version
GET/apps/:appId/deploymentsList deployments
POST/apps/:appId/restartRestart pods
POST/apps/:appId/scaleScale replicas
POST/apps/:appId/stop · /startStop or start an app
POST/apps/:appId/sleep · /wakeSleep or wake an app
GET/projects/:projectId/scheduled-deploymentsList scheduled deployments
POST/projects/:projectId/scheduled-deploymentsSchedule a deployment

Deploy request body — environment is required:

{
  "environment": "production",
  "tag": "v1.2.3",
  "reason": "hotfix for #412",
  "commitSHA": "7f3c9a1"
}

To deploy from git instead of a pre-built tag, send type: "git" with a git reference:

{
  "environment": "production",
  "type": "git",
  "git": { "branch": "main" }
}

Builds

MethodPathDescription
POST/apps/:appId/buildsTrigger a build
GET/apps/:appId/buildsList builds
GET/apps/:appId/builds/:buildIdGet a build
GET/apps/:appId/builds/:buildId/logsBuild logs
POST/apps/:appId/builds/:buildId/cancelCancel a build
GET/git/repos · /git/branchesRepos and branches available to the GitHub App

Config, secrets & env vars

MethodPathDescription
GET/apps/:appId/envs/:env/envvarsList non-secret env vars
POST/apps/:appId/envs/:env/envvarsSet env vars
DELETE/apps/:appId/envs/:env/envvars/:keyDelete an env var
GET/apps/:appId/envs/:env/secretsList secret keys (values hidden)
POST/apps/:appId/envs/:env/secretsSet a secret
GET/apps/:appId/envs/:env/secrets/revealReveal secret values
GET/secretsList all secrets (metadata)
PUT · DELETE/secrets/:secretIdUpdate or delete a secret
GET · POST/secrets/registryManage registry (image pull) secrets
GET · POST/projects/:projectId/shared-secretsProject-scoped shared secrets
POST · DELETE/apps/:appId/shared-secretsBind or unbind a shared secret

Observability & operations

MethodPathDescription
GET/apps/:appId/logsStream logs (SSE)
GET/apps/:appId/logs/wsStream logs (WebSocket)
GET/apps/:appId/execInteractive shell into a pod (WebSocket)
GET/apps/:appId/metricsCPU/memory metrics
GET/apps/:appId/metrics/prometheusPrometheus metrics for the app
GET/apps/:appId/diagnosticsWhy an app is unhealthy
GET/apps/:appId/files · /files/readBrowse and read files in a pod
POST/apps/:appId/files/writeWrite a file in a pod
GET/apps/:appId/cronjobs/statusCronJob statuses
POST/apps/:appId/cronjobs/:name/triggerTrigger a CronJob now
GET · PUT/apps/:appId/rate-limitsIngress rate limits
GET/health/dashboardCluster-wide health dashboard

Notifications & alerts

MethodPathDescription
GET · POST/projects/:projectId/notificationsManage notification channels
PUT · DELETE/projects/:projectId/notifications/:channelIdUpdate or delete a channel
POST/projects/:projectId/notifications/:channelId/testSend a test notification
GET/projects/:projectId/notifications/historyDelivery history
GET · POST/projects/:projectId/alertsManage alert rules
PUT · DELETE/projects/:projectId/alerts/:ruleIdUpdate or delete an alert rule

Add-ons

MethodPathDescription
GET · POST/projects/:projectId/addonsList or create managed datastores
DELETE/projects/:projectId/addons/:nameDelete an add-on
GET/projects/:projectId/addons/:name/credentialsConnection details for an add-on
POST/apps/:appId/addonsBind an add-on’s credentials into an app
DELETE/apps/:appId/addons/:nameRemove a binding

Cost & quotas

MethodPathDescription
GET/projects/:projectId/costsProject cost, grouped by app or environment
GET/apps/:appId/costsOne app’s cost
GET/projects/:projectId/environments/:env/quotaConfigured quota, plus what is committed and used
PUT/projects/:projectId/environments/:env/quotaSet an environment’s quota

Cost responses accept ?window= (24h, 7d, 30d, 90d, or a Go duration) and ?groupBy=app|environment. Every response reports the rate card it used and whether those rates are the built-in estimate, so a figure can be checked rather than taken on trust.

Quota responses report committed — what the environment’s apps add up to at their autoscaling maximum — alongside wouldExceed, which says whether enforcing the configured quota would already refuse work.

Git connections & repositories

MethodPathDescription
GET · POST/settings/git-connectionsList or add a GitHub, GitLab or Bitbucket connection
DELETE/settings/git-connections/:connectionIdRemove a connection
GET/git/reposRepositories across every connection
GET/git/branchesBranches for a repository

Registry credentials

MethodPathDescription
GET · POST/secrets/registryList or create registry credentials
DELETE/secrets/registry/:nameDelete a credential
GET/secrets/registry/:name/repositoriesRepositories the credential can see
GET/secrets/registry/:name/tagsTags for a repository (?repository=)
POST/secrets/registry/:name/testCheck the credential against its registry

Creating a credential accepts scope (global or project) and, for a project-scoped one, project. Only an administrator can create a global credential. A credential you may not use is absent from the listing and returns 404 rather than 403 when addressed directly.

Platform settings

MethodPathDescription
GET/settings/securityPod hardening profile, network isolation, default secret scope
PUT/settings/securitySet the platform security posture (admin)
GET · PUT/settings/rbacPer-project role enforcement
GET/users/me/permissionsWhat the caller may do, per project and environment

GET /settings/security is readable by any authenticated user; writing it requires an administrator. Under the restricted profile an app runs as a non-root user with a read-only filesystem, so a developer who cannot see the profile has no way to explain their own app’s failure to start.

Its observed field reports, per environment, whether network policies are actually being enforced — which is a different question from whether isolation is turned on, because NetworkPolicy is enforced by the cluster’s network plugin rather than by Kubernetes.

Users, teams & audit

MethodPathDescription
GET/users/meCurrent user
PUT/users/me · /users/me/passwordUpdate profile or password
GET/usersList users (admin)
POST/auth/registerCreate a user (admin)
GET · POST/teamsList or create teams
GET · PUT · DELETE/teams/:teamIdManage a team
POST · DELETE/teams/:teamId/membersAdd or remove team members
GET · POST/auth/tokensList or create API tokens
DELETE/auth/tokens/:idRevoke an API token
GET/audit-logsAudit log
GET/activityActivity feed
GET/webhook-deliveriesWebhook delivery log (admin)
GET/templatesApp templates
POST/templates/:id/deployDeploy from a template